HNHacker News
TopNewBestAskShowJobs

smashed

1,617 karma · joined December 7, 2015

Email: veilleux.cedric@gmail.com Github: https://github.com/cveilleux
submissionscomments
smashed··on AI is stifling new tech adoption?
It does not really matter as even though the models get updated, the new data was produced with the help of the older models, it is feeding on itself.

Just imagine how hard it would be to push a new programming language. No AI models would be able to generate code in that new language, or they would be extremely limited. This would make adoption much more difficult in a world where all developers use AI tooling extensively.

I believe this trend could create new opportunities also: as everyone uses AI tools to generate statistically average quality code, only those not using AI tools will be able to create true innovation.

smashed··on Making Beautiful API Keys
I don't quite understand the need for a timestamp. This only reduces entropy? You wouldn't think of using the current date in a password prefix for example.

Aren't you going to track the keys in a database, where you can keep the tenant id and creation time, scope of the key and any other significant metadata anyway?

A static prefix + checksum, maybe a version number so you can future-proof the system sounds like best practice. For example `ASKEY1-(128bit random base32 encoded)-(chksum)`.

smashed··on Show HN: BunkerWeb – The Open-Source Web Application Firewall (WAF)
I agree it might not be worth promoting as a main feature at all. But from experience, there are users that will be very vocal about it and request a dark mode.
smashed··on Intel gets up to $7.9B award for U.S. chip-plant construction
Investing in or doing it? Not the same.
smashed··on OpenWRT One Released: First Router Designed Specifically for OpenWrt
It's not openwrt even though they pretend it is in their marketing. It's based on openwrt and might be "compatible" to some level with other openwrt packages.

When asked for full source code they seem transparent about it:

https://forum.gl-inet.com/t/source-code-for-gl-firmware-and-...

You can't reproduce their images and they don't share the improvements.

Of course not GPL compliant but not a concern in China I believe.

smashed··on WireGuard: Beyond the most basic configuration
Tailscale will fallback to tuns servers which are dumb "cloud" relays if direct connection can't be established.
smashed··on Syncthing Android App Discontinued
It's my phone. It's my data. It's my choice to install the app. It's my choice to grant the permissions to all files. Because guess what, I'm using the app to sync all my files.

I really can't agree with Google in this particular case.

smashed··on HTTrack Website Copier
I've tried both in order to archive EOL websites and I've had better luck with wget, it seems to recognize more links/resources and do a better job so it was probably not a bad choice.
smashed··on The Art of the Brew: Exploring Hops and Other Plant Ingredients That Define Beer
It's a matter of terminology. From my understanding, some 200+ years ago in the UK, ale was used for non-hopped malt beverages and beer was used for hopped malt beverages.

The terms eventually evolved to mean the same thing, as pretty much all brews became hopped.

The interpretation will vary a lot depending on the culture and the century you are digging into.

Some references: https://zythophile.co.uk/2009/12/14/the-long-battle-between-...

smashed··on We spent $20 to achieve RCE and accidentally became the admins of .mobi
Magento, OpenCart or WooCommerce are money related. All terrible but also very popular. But I guess they work, somehow.

What would you use to build and self-host an ecommerce site quickly and that is not a SaaS?

smashed··on Orphaning bcachefs-tools in Debian
> I would rather something not be packaged at all than packaged badly; this whole experience reads like a lesson in what not to do.

You might consider adding a big warning on your official documentation about unsupported distribution packages.

Add links to relevant issue tracker/bug reports or mailing list discussions saying until So and so issue are resolved, the official statement is that distribution package is unsupported, not recommended and deemed dangerous to use.

This is as much leverage as you can have with the distribution community. Then wait for them to upstream patches and attempt to fix the issues. Accept fixes as you consider appropriate or not.

It's also important to at least respect the distribution's opinions in regards to having only one version of a library's major release . Just respect and understanding, you don't have to agree.

Also, all the problematic libs cited by the packager are 0.x.x numbered which sounds like a very young and immature ecosystem of dependencies. Of course, this is bound to cause pain to packagers. I think this speaks volumes about the high level of interest for bcachefs, that they actually tried to make it work instead of not bothering.

smashed··on Firewall rules: not as secure as you think
I understand the technical issue but on a broader sense, the instant that a vendor supplied black box is installed behind your firewall and allowed to make any sort of communication towards a vendor controlled endpoint, doesn't it immediately technically allows full remote control?

Lots of talk about tunneling and wrapping/disguising ssh but a vendor does not need any of that to control its machine.

For example you could have the on-prem host poll a "licensing" or "software update" server that also happens to reply with ad-hoc commands to execute on demand. Could be straight up shell commands and the result can be sent back. No need for ssh, long lived connections, reverse tunnels or anything.

The only way to mitigate this is to fully trust the vendor, have a strong legal framework to protect against wrongdoings or fully block all internet access to endpoints you don't fully control.

smashed··on A Gentle Introduction to SAML
Oidc middlewares already exist. Many authentication providers/software call it "federated login" or "social login" where they can delegate the credentials to a third party if so configured.

Maybe clarify what you can do better or different or just how exactly you're doing it and let the audience decide.

smashed··on Google scrambles to manually remove weird AI answers in search
The problem is that in all the shared examples, Google ai search does not respond with a Maybe xyz, question mark? like you did. It always answers with high confidence and can't seem to navigate any gray area where there are multiple differing opinions or opposing source of truths.
smashed··on RISC-V support in Android just got a big setback
> We received some disappointing feedback from a key organization in the RISC-V ecosystem that the Yocto Project was not important and not worth funding. We will take this feedback into account.

That's a bummer. But the core Risc-V support should be contributed straight to the Linux kernel/u-boot/gcc/glibc anyway I guess. Then board makers, not chip makers, should contribute/provide yocto support, based on that foundational work.

Not sure which key organization they are referring too though.

smashed··on Cosmic Desktop: Hammering Out New Cosmic Features
Linux is a bazaar. Very chaotic, nothing is ever perfect, but there is something for everyone that sets foot.
smashed··on Going in circles without a real-time clock
> I figured they must be running DNSSEC on that zone (or some part of it), and it must have a "not-before" constraint

Since clients will attempt to resolve ntp.org in order to actually sync their clock, there is a good probability that some clients will be way off.

Enabling dnssec on that zone was probably not without important drawbacks? I wonder if the operators thought about that potential pitfall. Seems like they might be doing a disservice to their core mission of allowing devices to sync their clock.

smashed··on Command injection and backdoor account in D-Link NAS devices
I've seen compromised iot devices used to run proxy servers. They are mostly resold on black market as residential IPs for web scrapping and such. Since there is a black market for it they mostly get resold, instead of put to use on the free TOR network I guess.

Residential ISPs usually monitor the blacklisting of their IP addresses and will contact/suspend the customer once the IPs get listed on public black lists.

smashed··on OpenSSH and XZ/liblzma: A nation-state attack was thwarted, what did we learn?
Good tidbit in there that systemd was about to ship an optimization that rendered their payload non-functional:

https://github.com/systemd/systemd/pull/31550

This might be why they started rushing their backdoored release, even though it was not perfect yet.

smashed··on Xz: Can you spot the single character that disabled Linux landlock?
A misplaced punctuation has some plausible deniability. Like the author could say he was distracted and fat fingered nonsense, honest mistake.

A utf character from a language that has zero chance of being mapped to your programmer's keyboard in the middle of a code line, that would be obvious intentional tampering or at the very least raise some eyebrows.

smashed··on Allegations of criminality by Boeing in deceased whistleblower complaint
That is still more or less voluntary manual recording, sprinkled with micro management vibes.

What's at stake here is systematic and transparent recording of all video and audio conversation.

Does it exist? Does ms teams for example has an enterprise feature available to record and archive everything without the meeting organizer activating the recording explicitly?

smashed··on Django REST framework 3.15.0
Most major PHP frameworks like laravel, symfony, Drupal, Magento develops all kinds of complex caching layers to work around PHP's stateless 1 request/1 execution model, essentially poorly recreating shared application state you would get for free with a long running worker process.

Python's import model is not without its flaws either, but at least you have a working application state, no need to fully initialize your app for every single request.

For simple apps that are contained within a few files, PHP is hard to beat for simplicity and speed.

smashed··on Mozilla will be retiring the Mozilla Location Service
No but if Walmart distributes 81% of the production of that particular cracker brand, it could suddenly find itself in a huge crisis if Walmart decided to cease distributing it and fill the shelves with great value crackers.
smashed··on Improving Network Performance with Linux Flowtables
I was confused with this as well and the documentation is not always clear about it.

Nftables and the netfilter project is the firewall implementation in Linux.

The legacy and beloved iptables format is fully replaced nowadays by nftables. You don't have to learn anything new because the iptables command line is just a compatibility layer on top of nftables with full compatibility. When you insert iptables rules, they get translated to nftables seamlessly. This has been the default on all major distros for years.

Converting to nftables has a few neat advantages such as much improved set/map and verdict tables support, unified IPv4, IPv6 and bridge rules, etc. But you don't have to. Everything old still works.

Flow tables is an optional feature of netfilter, I think originally meant to interface with hardware NAT accelerators in cheap routers, but it also has a pure software default implementation that can speed things up in some cases. That's what is being discussed in this article.

You use nftables to define and hook into flow tables. They work together, not against each other.

smashed··on Supermium – Chromium fork for Win 2003/XP and newer
A modern Linux distro with an older generation desktop environment like MATE or xfce is incredibly snappy, has modern hardware support and is maintained with security updates and up to date crypto stack.
smashed··on Google pays publishers to test AI tool that scrapes sites to craft new content
Nothing wrong with AI generated content if it's info I need and it's factually correct.

The problem I have is that it's usually junk fluff pieces with way too much text for SEO optimization.

I feel anything computer generated should be short bullet points or comparison tables, not long form text as it's just not good at that.

For example think of a blog post where the author walks you through its thought process, trial and error and ultimate solution. That is very humane and relatable, something an LLM can approximate/copy but it will never be genuine. I'd prefer in that case just the raw solution, not a fake and deceptive walkthrough.

smashed··on A Few Jelly Beans and a World of Disappointment at Willy Wonka Event
Really not the kind of mistakes generative AI makes.
smashed··on Earth just experienced its hottest 12 months in recorded history
I see an upward line starting from the 1920's onward if you focus on the general trend.
smashed··on Plastic experts say recycling is a scam. Should we even do it anymore?
After the stone, bronze and iron age, we are definitely in the plastic age now.
smashed··on Eclipse viewing at 30k feet: Delta to offer path-of-totality flight
https://eclipse.aas.org/eye-safety/viewers-filters

And buy direct, don't use Amazon because of the counterfeit risks.

← PreviousPage 4 of 11Next →